1Entity Scope & Commitment
This Privacy Policy outlines how Vexel Systems ("we", "us", "our"), headquartered in Vavuniya, Sri Lanka, collects, uses, stores, and protects personal and commercial data across our official websites, custom client web platforms, mobile applications, and proprietary retail solutions including Vexel POS.
We operate in strict adherence to the Personal Data Protection Act No. 9 of 2022 (PDPA) of Sri Lanka and conform to international security and privacy best practices (including GDPR principles for our global clients in the UK, Australia, Singapore, and UAE).
2Information We Collect
We adhere to strict data minimization principles. We only collect information strictly required to deliver, license, and maintain software services:
- Contact & Account Credentials: Authorized merchant names, work email addresses, telephone/WhatsApp numbers, billing details, and encrypted authentication credentials.
- Point of Sale & Inventory Metadata: Product SKU lists, barcode structures, sales receipts, transaction totals, and stock balance events necessary for multi-branch sync.
- Hardware & Operational Telemetry: Thermal printer connection status, local device network identifiers, POS register IDs, software version tags, and sync error logs.
- Customer Inquiries & Project Specifications: Information voluntarily submitted through our interactive project configurator, contact forms, or direct engineering consultations.
3Client Data Ownership & Zero Monetization
Zero-Monetization Pledge
Vexel Systems maintains a strict, unconditional zero-monetization policy. Your sales logs, customer contact lists, item margins, and retail turnover remain 100% your proprietary property. We never sell, rent, monetize, or disclose your commercial records to third-party advertisers or data brokers.
Unlike ad-supported platforms or aggregators, Vexel Systems generates revenue solely through software engineering, POS licensing, and technical support services. Your business data belongs solely to your organization.
4How We Use Your Information
All collected data is processed on lawful, contractually defined grounds for specific commercial purposes:
Service Delivery & Sync
Executing real-time branch synchronization, cloud backups, and local offline transaction caching.
Security & Role Verification
Enforcing role-based cashier access controls, manager overrides, and tamper-proof shift audit logs.
Automated Digital Receipts
Delivering end-customer electronic receipts via WhatsApp or SMS solely upon buyer request at checkout.
Technical Support SLA
Investigating network drops, printer driver conflicts, and resolving operational discrepancies rapidly.
5Data Security & Cryptographic Storage
We implement defense-in-depth security architectures designed to safeguard records against unauthorized interception, hardware theft, or cyber threats:
- Encryption in Transit: All communications between POS counter registers, mobile apps, and central cloud servers are enforced through TLS 1.3 encryption.
- Encryption at Rest: Cloud database tables, customer backups, and sensitive configuration tokens are encrypted using AES-256 standard cryptographic suites.
- Offline Local Database Isolation: Local counter databases operating during internet outages are stored within isolated, password-protected instances that require authenticated cashier credentials.
- Credential Hashing: Staff passwords and manager PINs are stored using salted cryptographic one-way hashes; plain-text credentials are never saved.
6Sub-Processors & Infrastructure Providers
To ensure high uptime, secure hosting, and electronic receipt dispatch, Vexel Systems partners with verified enterprise infrastructure providers bound by rigorous Data Processing Agreements (DPAs):
- Cloud Hosting & Datacenters: Enterprise cloud hosting (AWS / DigitalOcean / Supabase) located in secure, SOC2-certified regional datacenters.
- Digital Messaging Gateways: Meta Cloud API / Twilio for automated WhatsApp and SMS e-receipt dispatch triggered at the point of sale.
- Payment Gateways: Direct integration with licensed Sri Lankan bank IPGs (Commercial Bank, Sampath, PayHere) complying with PCI-DSS standards.
7Data Retention & Permanent Erasure
We retain customer transaction logs and project records only for the period necessary to fulfill contractual services, maintain system continuity, and satisfy statutory accounting obligations under Sri Lankan tax regulations.
Upon contract termination or upon formal written request, clients may export 100% of their historical databases in open formats (SQL dump or CSV). Following verified handover, our engineering desk initiates a certified, irreversible data purge from all staging and live environments.
8Your Statutory Rights (PDPA & GDPR)
Under the Sri Lanka Personal Data Protection Act No. 9 of 2022 and international data protection standards, data subjects possess the following enforceable statutory rights:
- Right of Access: Request a complete, machine-readable copy of any personal data processed under your organization's account.
- Right to Rectification: Request immediate correction of inaccurate, incomplete, or outdated business or contact information.
- Right to Erasure: Request the permanent deletion of non-essential records where lawful retention grounds no longer apply.
- Right to Restrict or Object: Withdraw consent for optional analytics or automated performance telemetry at any time.
9Policy Amendments & Compliance Contacts
We review this Privacy Policy periodically to reflect technological advancements, new POS features, and evolving regulatory mandates. Material amendments will be highlighted via notice on our website and directly to active business accounts.
For questions, audit requests, or data privacy inquiries, contact our Data Protection Officer at privacy@vexelsystems.lk.
Have questions about your business data?
Our software architects and privacy compliance officers are available to review security protocols, execute bilateral NDAs, or provide detailed data governance documentation.
Contact Privacy Desk